{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:26c8365e-8082-552b-815a-0d9cad6033d7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-catalina-ha",
      "version": "9.0.90-tuxcare.4",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9d17b848-6e84-5743-b6a0-e263afea2697",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af659d01-8a13-5a6c-ba25-7acef8179274",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d97aea77-6754-54c0-83b9-70cb0af68502",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:460f8748-8605-5619-a81d-d39ec98f70b0",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e18eac14-e055-5b73-86d0-1605893dcf70",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c972ce7c-a5d7-5f99-a3c0-e5c59cd6268b",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bd6bbd9-9c7c-56bb-9282-cc2d1f150ac5",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7cb283d-e043-517e-b0c5-523eb44117d4",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:828e8567-dd79-5570-b3f2-6171abd577c0",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6202108-5118-5883-8b4e-d2e82f20a021",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28c2575b-9b5f-5582-ba28-2147acd494c6",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:848f5e2c-6a2c-5508-b834-25339b966053",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2142d831-c54f-5b19-b25d-9a99c0cdb6dc",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:455e1cbc-efde-59e8-8551-74aebbf7eab4",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0b98a6c-af46-5762-8ecc-0bd3968b86c5",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1495d935-4f52-5bde-a9bd-7cb09bf665d2",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64d45d77-3346-5963-a861-48c2b95816ef",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72fd427f-4289-5547-bdfe-8bed4674be7f",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77adc649-957b-5b23-97c1-f1cf040ab7f0",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4a48075-1be1-5c57-897d-706ac9fa01a3",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:576d29d4-3ac7-564c-8a71-d2560fe85910",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ea5e182-a93c-5e31-bffe-f5cd0b0e3071",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4298c44b-fdd3-5cd9-a678-d9b044abb3dd",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fb323cd-e064-5289-a5f6-1c38a23dc955",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c360a2f-a0b4-5246-9ddc-35ad2752b82e",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2775ef3-8d46-501a-bd47-ab5a4207619e",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce0e3b58-ab0f-567d-996d-fe074a7adba3",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc86914f-b84c-532c-83e4-342a52067625",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7c7bcde-3a65-5dec-a7e5-9592faf44936",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aed8905a-4a0f-5045-a947-f1f9c9f70c2b",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2777b0b-62c5-5132-85da-9396f67dcd44",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2259d894-2eab-53f9-8306-eb78d35c1b92",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:743c486d-7601-536a-aaaf-de0ee6bda32d",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5783cbbb-def2-567e-9e70-ec83839242b1",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d02340d-5fdc-5349-97ae-ef72336b2ff4",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57f87ec4-62ee-5375-a6c5-1a8a09ca3960",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33e24116-59dc-5524-be16-d3f428f0c705",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2e339a7-2a94-518f-863c-d769a28f7620",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abc81ae1-e03c-5e11-b024-0a00479c6536",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.90-tuxcare.4"
    }
  ]
}